Infosec News Nuggets — July 28, 2026
Brief
Hackers Target US Firms in FastJson RCE Zero-Day Attacks
Attackers are actively exploiting a critical remote code execution flaw in the open-source FastJson Java library, a widely used component in Alibaba-linked enterprise software, without needing user interaction or elevated privileges. Tracked as CVE-2026-16723, the bug affects versions 1.
- 68 through 1.
- 83 under common Spring Boot fat-JAR deployments and stems from type-resolution logic that allows malicious classes to load before AutoType restrictions kick in. Attacks are currently concentrated on organizations in financial services, healthcare, computing, and retail across the US, with some spillover into Singapore and Canada. Since FastJson 1.
x is no longer actively maintained, no patch is expected, leaving affected users to enable SafeMode or migrate to a non-vulnerable build as their only real options.
